[x]
Posted via EE Mobile

Search, ask, and monitor your questions on the go with EE Mobile. Visit Experts Exchange from your mobile device and never be out of touch again.

Question
[x]
Attachment Details
[x]
The Solution Rating System

With so many solutions, how can you tell which solutions are most likely to help you and which ones are not? To provide you with a tool to use, we rate our solutions based on various elements that most accurately determine if a solution is a quality solution. To explain what factors affect the solution rating, here are the elements we take into consideration when formulating our solution rating.

  • The Grade of the Solution
  • The Zone Rank of the Expert Providing the Solution
  • The Number of Author and Expert Comments
  • The Number of Experts Contributing
  • The Feedback of the Community

Your Input Matters
Because of the way the system is set up, the most important variable in this equation is you. As a member of Experts Exchange, you are able to cast your vote on the quality of the solutions in regard to how complete, accurate, helpful and easy to understand each solution is. When you provide your feedback, each rating is adjusted accordingly. So, if you see a solution that has a poor rating that you think is a good solution, let us know by rating it. As you do, the rating will be adjusted and will become more accurate for other members of our site.

If you have any suggestions that you would like to make for our rating system, please ask a question in the Suggestions Zone of Community Support.

Thank you!

9.3

VPN between two ZyWall 2+ (Dynamic-to-Dynamic)  -  IKE Packet retransmit problem

Asked by fpifferini in Virtual Private Networking (VPN), IPSec Security Protocol, Networking Hardware Firewalls

Tags: VPN, IKE Packet Retransmit, ZyWall

Hello,
I would like to connect two offices using a VPN tunnel, but Ive some difficulties.

Here the configurations:

Site1:
------
- ADSL with dynamic IP from the Provider, registered at DynDNS.org to have the host name available (site1.dyndns.org).
- The ADSL router (Motorola) as the LAN side configured to act as DHCP server on the range 192.168.20.0/24
- A ZyWall 2+ is connected to this router and get the IP address from it.
  - In the DDNS settings on the ZyWall Ive the entry for site1.dyndns.org
  - FW is enabled
  - LAN is configured to be DHCP server to provide IP addresses to the PCs in the office (IP range 192.168.2.0/24)

VPN settings for Site1:
Gateway Policy Property Name:      CompanyNetwork

Gateway Policy Setting
  My ZyWALL:                  site1.dyndns.org
  RemoteGateway Address:      site2.dyndns.org

Network Policy Property
  Active:                  YES
  Name:                  Site1-To-Site2

Network Policy Setting
  Local Network
    Starting IP address:      192.168.2.1
    Subnet Mask:            255.255.255.0
   
    Remote Network:            192.168.1.1
    Subnet Mask:            255.255.255.0

IKE Tullel Setting (IKE Phase 1)
  Authentication for activating VPN
     Authentication By
     User Name
     Password
  Negotation Mode:            Main Mode
  Encryption Algorithm:            3DES
  Authentication Algorithm :      SHA1
  Key Group :                  DH2
  SA Life Time:                  28800 s
  Pre-Shared Key:            MySharedKey1

IPSec Setting (IKE Phase 2)
  Encapsulation Mode:            Tunnel Mode
  IPSec Protocol:            ESP
  Encryption Algorithm :      DES
  Authentication Algorithm :      SHA1
  SA Life Time:                  28800 s
  Perfect Forward Secrecy (PFS): None



Site2:
------
- ADSL with dynamic IP from the Provider, registered at DynDNS.org to have the host name available (site2.dyndns.org).
- The ADSL router (ZyXEL P600H-D3) as the LAN side configured to act as DHCP server on the range 192.168.10.0/24, FW disabled
- A ZyWall 2+ is connected to this router and get the IP address from it.
  - In the DDNS settings on the ZyWall Ive the entry for site2.dyndns.org
  - FW is enabled
  - LAN is configured to be DHCP server to provide IP addresses to the PCs in the office (IP range 192.168.1.0/24)

VPN settings for Site2:
Gateway Policy Property Name:      CompanyNetwork

Gateway Policy Setting
  My ZyWALL:                  site2.dyndns.org
  RemoteGateway Address:      site1.dyndns.org

Network Policy Property
  Active:                  YES
  Name:                  Site2-To-Site1

Network Policy Setting
  Local Network
    Starting IP address:      192.168.1.1
    Subnet Mask:            255.255.255.0
   
    Remote Network:            192.168.2.1
    Subnet Mask:            255.255.255.0

IKE Tullel Setting (IKE Phase 1)
  Authentication for activating VPN
     Authentication By
     User Name
     Password
  Negotation Mode:            Main Mode
  Encryption Algorithm:            3DES
  Authentication Algorithm :      SHA1
  Key Group :                  DH2
  SA Life Time:                  28800 s
  Pre-Shared Key:            MySharedKey1

IPSec Setting (IKE Phase 2)
  Encapsulation Mode:            Tunnel Mode
  IPSec Protocol:            ESP
  Encryption Algorithm :      DES
  Authentication Algorithm :      SHA1
  SA Life Time:                  28800 s
  Perfect Forward Secrecy (PFS): None

-----
When I test the connection, VPN tunnel is not established.
In the LOG of both ZyWall's I see that the DNS resolution of the 2 sites are OK,
but I've the error:     IKE Packet Retrasmit

I've try in different way to debug it but without success.

Do you have any idea what could be the problem?
How can I have a more detaield log for helping debugging?

Thank you for your help.
FP
 
Related Solutions
Keywords: VPN between two ZyWall 2+ (Dyna…
 
Loading Advertisement...
 
[+][-]04/30/09 12:55 PM, ID: 24273777Accepted Solution

View this solution now by starting your 30-day free trial. Setting up your free trial is quick, easy, and secure. We will return you to this solution, unlocked, when you're done.

About this solution

Zones: Virtual Private Networking (VPN), IPSec Security Protocol, Networking Hardware Firewalls
Tags: VPN, IKE Packet Retransmit, ZyWall
Sign Up Now!
Solution Provided By: arnold
Participating Experts: 1
Solution Grade: A
 
 
Loading Advertisement...
20091021-EE-VQP-81 - Hierarchy / EE_QW_3_20080625